SQL injection vulnerability in Gandia Integra Total
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 8.7epss 1.1%
from disclosure to weapon0 days
Published on NVDAug 1
1st PoCAug 1
exploitation probability
1.1%top 37% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb[_v4]/integra/html/view/hislistadoacciones.php.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
TESI · Gandia Integra Totalpublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/52388unverifiedgithubgithub.com/byteReaper77/CVE-2025-41373★ 2⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.